Nimi Runtime is the local Go daemon and CLI behind Nimi's app-facing AI surface.
It owns:
- local and cloud execution
- streaming and health
- model lifecycle
- knowledge, app messaging, and audit
If you are using Nimi as a product, use the installed nimi binary.
On a build with an admitted background/service controller:
nimi start
nimi doctor
nimi statusForeground/developer path:
nimi serveConnector custody and ModelAsset/Loadout selection are exposed only through Desktop's verified protected Runtime surface. The CLI and standalone SDK clients do not own parallel provider credentials, model selection, or generation routing.
Core command groups:
servestartdoctorinitversionstatusstoplogs
Advanced runtime groups:
knowledgeappaudithealthconfig
Run nimi <command> --help for the current command contract.
App-facing inference uses the SDK's typed Runtime clients after Desktop's verified protected surface has committed Connector and Loadout intent.
If you are developing Nimi Runtime itself from this repo, use the source entrypoint:
cd runtime
go run ./cmd/nimi servedoctor, status, and health use only an admitted daemon manager or
service controller. They fail explicitly on builds without that background
topology; they do not probe a protected Runtime method or invent a fallback
process.
Production Runtime private configuration is service-principal-owned protected
state. ~/.nimi/runtime/config.json, ~/.nimi/config.json, and
NIMI_RUNTIME_CONFIG_PATH are not production discovery or migration inputs.
Product data discovery starts only at ~/.nimi/nimi.json; Runtime independently
validates its dataRoot.path and retains only derived verification state.
Registered public runtime gRPC services currently include:
RuntimeAiService— local and cloud AI execution, streaming, multimodalRuntimeAiRealtimeService— duplex realtime text/audio session surfaceRuntimeLocalService— local model inventory, Loadouts, acquisition, and supervisionRuntimeAgentService— live agent execution, hook lifecycle, and Runtime-mediated LocalAgent MemoryRuntimeConnectorService— provider connector lifecycle, credential hostingRuntimeAuthService— authentication and token managementRuntimeAppService— app messaging and registrationRuntimeAuditService— audit logging and replay
Notes:
- Cognition is an in-process owner reached only through typed Runtime-owned bridges; the pre-V1 generic Cognition gRPC service and Knowledge CLI are not public surfaces.
- standard
grpc.health.v1.Healthprobing is also registered for daemon health, but it is not part of the runtime-owned proto service inventory above.
The explicit nonproduction foreground configuration may expose:
- gRPC on
127.0.0.1:46371by default - HTTP health endpoints on
127.0.0.1:46372by default
Production does not open these ordinary listeners. Desktop reaches protected Runtime methods through the verified native transport.
CLI runtime management semantics:
serve: foreground runtime with direct logsstart: admitted background/service start, otherwise bounded unsupported failurestatus: process status + reachability summaryhealth: sanitized daemon process or protected-service health summarylogs: managed background log tail
Health endpoints:
GET /livezGET /readyzGET /healthzGET /v1/runtime/health
- Product Control has the fixed path
~/.nimi/nimi.json; only itsdataRoot.pathselects product data storage. - Production Runtime private configuration has an OS-specific protected path that is not a Desktop, SDK, or public CLI interface.
- The source-development portable config surface is non-production only and
exists only when
NIMI_RUNTIME_CONFIG_PATHexplicitly names a non-retired path. It has no default discovery, rejects~/.nimi/runtime/config.json, and rejects Product Control-owneddataRootRefandmanagedRootsfields. - Runtime managed roots are derived from the selected data root and protected state cannot select or override it.
- Provider credentials may use
apiKeyorapiKeyEnv, but never both - User-facing setup should prefer env-backed credentials; inline
apiKeyis fallback-only configchanges that touch runtime wiring remain restart-scoped- Connector/provider authority is the repo-local
.nimispec surface:.nimi/spec/runtime/ai-provider.authority.yaml,.nimi/spec/runtime/model-catalog.authority.yaml, and imported kernel provider catalog/capability tables. Runtime catalog source files and generated snapshots are support/projection inputs, not standalone product truth.
From the repository root:
Use Python 3.12 in an activated virtual environment. Install the pinned numerical test dependency before running the Python suite; this does not install models or change an execution profile.
python -m pip install --requirement runtime/test-requirements.txt
pnpm test:runtime:go
pnpm test:runtime:pythonProvider live smokes are opt-in and require their corresponding
NIMI_LIVE_* credentials:
pnpm test:runtime:livepnpm proto:breaking 对照的是已发布的 wire:
runtime/proto/runtime-v1.baseline.json 记录其来源(携带 wire 的组件
tag、提交与已发布制品),runtime/proto/runtime-v1.baseline.binpb 必须能从该
tag 的 proto/ 逐字节重建。门禁不接受从未发布源码刷新的快照。
- 有意的破坏性 wire 变化:在记录的
declaredBreaking中写明 buf 的规则、路径、 消息、原因,以及新 0.x minor 在 CHANGELOG 中的迁移说明标题。 - 携带 wire 的组件发布后,从该 tag 刷新基线,并记录与上一基线的差异裁决:
pnpm proto:baseline:refresh -- --tag sdk/v<SemVer> \
--published npm:@nimiplatform/sdk@<SemVer>,... \
--adjudication "<对差异的审阅结论>"- Runtime reference: docs/reference/runtime.md
- Runtime domain authority: .nimi/spec/runtime — one
container per area;
rpc-foundations.authority.yamlandprotected-session.authority.yamlcarry the transport and session contracts that the per-filekernel/tree used to hold. - Contributor workflow: CONTRIBUTING.md